HomeProductsAIServicesIntegrationsCompany

Privacy Policy

01Who we are

Purplecop Security operates through separate contracting entities. The entity that contracts with you is the one responsible for your personal data, and which data protection law leads depends on that entity and on where you are.

Questions about this policy: [email protected]. [a dedicated privacy@ mailbox is expected on a privacy vendor — confirm whether one exists]

RegionContracting entityRegistered addressPrimary regime
United StatesPurplecop Security Inc.4070, 1007 N Orange St, 4th Floor, Wilmington, DE 19801, New Castle County, USAapplicable US federal and state law, including the CCPA/CPRA where it applies
India[registered Indian entity name][India registered address]Digital Personal Data Protection Act, 2023
Dubai, UAE[registered UAE entity name][UAE registered address]UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection

02Controller and processor — which one we are

This distinction decides which obligations apply, so it is stated first rather than buried.

  • We are the controller for personal data about our own website visitors, prospects, customers’ contacts, partners, job applicants and employees. That is the data this policy governs directly.
  • We are the processor for personal data our customers put into the products — their employees, their vendors, their own data subjects. We process it on their documented instructions under a Data Processing Agreement, and the customer remains the controller. Where this policy and a signed DPA differ, the DPA governs.

03What we collect

We do not buy personal data from data brokers, and we do not ask for special-category data. Please do not send it to us in an enquiry.

  • Information you give us — name, work email, company, role and anything you write in a message, when you request a walkthrough or contact us.
  • Product data — account identifiers, configuration, and the security and compliance data you connect to the products.
  • Technical data — IP address, browser and device type, pages viewed and referring page. See the Cookie Policy.
  • Practice Lab data — for GRC Practice Lab users: registration details and learning progress.

04Why we use it, and our lawful basis

Under the DPDPA, where we rely on consent you may withdraw it at any time, and withdrawing must be as easy as giving it. [confirm the withdrawal mechanism — link or mailbox]

PurposeGDPR basisDPDPA basis
Responding to an enquiry or running a demoLegitimate interests / steps before a contractConsent, or a legitimate use where applicable
Providing and supporting the productsPerformance of a contractPerformance of a contract
Securing our own systems and preventing abuseLegitimate interestsLegitimate use
Marketing to business contactsLegitimate interests, or consent where requiredConsent
Meeting legal, tax and regulatory obligationsLegal obligationLegal obligation

05Your rights

The rights you hold depend on which law applies to you. We honour the following, and we do not charge for a first request.

To exercise any of these, write to [email protected]. We respond within [response window — must satisfy the strictest applicable law]. If your data is in a platform operated for one of our customers, we will refer you to that customer, who is the controller.

Grievance Officer (India): [name], [designation], [email], [postal address]. The DPDPA requires these details to be published.

  • Access — a copy of the personal data we hold about you, and a summary of the processing.
  • Correction and completion — correction of inaccurate data, and completion of incomplete data.
  • Erasure — deletion where we no longer have a basis to keep it.
  • Grievance redressal (DPDPA) — a readily available means to raise a grievance with us before approaching the Data Protection Board of India.
  • Nomination (DPDPA) — the right to nominate a person to exercise your rights in the event of death or incapacity.
  • Objection, restriction and portability (GDPR) — where those rights apply to you.
  • Opt out of sale or sharing (CCPA/CPRA) — we do not sell personal data, and we do not share it for cross-context behavioural advertising.

06Sharing and sub-processors

We share personal data only where there is a reason to, and every recipient is bound by contract.

We do not sell personal data.

  • Service providers who host, secure or support the products — listed on the Sub-processors page.
  • Professional advisers, auditors and insurers, where they need it to do their work.
  • Authorities, where the law compels disclosure. We notify the customer unless legally prohibited.
  • An acquirer, if the business or part of it is sold — with notice to you.

07International transfers

We operate in the USA, India and Dubai, so personal data may be processed outside the country it was collected in.

[confirm the actual transfer mechanisms in place, and the countries data reaches]

  • From the EU/UK — Standard Contractual Clauses, plus a transfer risk assessment where required.
  • From India — transfers permitted under the DPDPA other than to a country restricted by the Central Government.
  • From the UAE — transfers on the bases permitted by the UAE data protection law.

08How long we keep it

When a retention period ends we delete the data or irreversibly anonymise it.

  • Google Analytics data: anonymised, and automatically deleted after 2 years.
  • Enquiry and prospect data: [retention period]
  • Customer account and product data: for the term of the contract, then [post-termination deletion window]
  • Security logs: [retention period]
  • Records we must keep by law: for the statutory period

09Security

The controls protecting personal data are described on the Trust Center. No system is perfectly secure, but a breach is handled under the incident response process on the Security page, including notification to affected people and regulators where the law requires it — under the DPDPA, notification to the Data Protection Board and to each affected Data Principal.

10Children

Our platforms are sold to organisations and are not directed at children. Under the DPDPA, processing a child’s personal data requires verifiable parental consent and prohibits tracking and targeted advertising to children. We do not knowingly collect data from anyone under 18. If you believe we have, write to [email protected] and we will delete it.

11Changes to this policy

We will post any change here and update the date at the top. Where a change materially affects your rights we will give notice before it takes effect.